Typosquatting is the registration of deliberately misspelled or lookalike versions of a legitimate domain — gooogle.com, paypa1.com, micros0ft.com — to intercept mistyped traffic, run phishing, or damage a brand. You defend against it with a three-layer program: (1) defensively register a tight core set of high-risk variants (exact-match in .com/.net/.org and your ccTLD, plus the one or two most common typos and any pixel-identical homoglyph twin); (2) monitor the rest continuously — Certificate Transparency logs surface new lookalikes within seconds of a certificate being issued, days before they send mail; and (3) take down weaponized domains through UDRP (transfers the domain, ~$1,500, 2–3 months), URS (suspends it, ~$375, faster), or a registrar abuse notice when active phishing is involved.
That is the summary an AI Overview can give you. What it can't show you is the shape of the problem — how many variants a single brand actually spawns, which of the dozens of attack types matters, and the decision path from "I found a lookalike" to "it's gone." The diagram, the live analyzer, and the tables below make that concrete.
The problem is bigger than it looks: one brand, hundreds of variants
Every brand name is the seed of a large lookalike space. Attackers don't guess randomly — they work through a small number of well-known transformation classes, and each class multiplies with the others and with the ~1,500 available TLDs. The figure below shows how a single seven-letter brand fans out.
<rect x="30" y="160" width="180" height="40" rx="5" fill="#ffffff" stroke="#e2e8f0"/>
<text x="120" y="178" text-anchor="middle" font-weight="700">Duplication</text>
<text x="120" y="193" text-anchor="middle" fill="#b91c1c">accmebank.com</text>
<rect x="30" y="250" width="180" height="40" rx="5" fill="#ffffff" stroke="#e2e8f0"/>
<text x="120" y="268" text-anchor="middle" font-weight="700">Adjacent key</text>
<text x="120" y="283" text-anchor="middle" fill="#b91c1c">acnebank.com</text>
<rect x="550" y="70" width="180" height="40" rx="5" fill="#ffffff" stroke="#e2e8f0"/>
<text x="640" y="88" text-anchor="middle" font-weight="700">Transposition</text>
<text x="640" y="103" text-anchor="middle" fill="#b91c1c">acembank.com</text>
<rect x="550" y="160" width="180" height="40" rx="5" fill="#ffffff" stroke="#e2e8f0"/>
<text x="640" y="178" text-anchor="middle" font-weight="700">Homoglyph</text>
<text x="640" y="193" text-anchor="middle" fill="#b91c1c">аcmebank.com</text>
<rect x="550" y="250" width="180" height="40" rx="5" fill="#ffffff" stroke="#e2e8f0"/>
<text x="640" y="268" text-anchor="middle" font-weight="700">Alternate TLD</text>
<text x="640" y="283" text-anchor="middle" fill="#b91c1c">acmebank.co</text>
The takeaway: you cannot register your way out of this. Defensive registration is a containment tactic for the highest-risk handful; monitoring and takedown handle the long tail.
See it live: analyze a domain or generate protective variants
The tool below runs the same transformations an attacker would. Enter a suspicious domain to score its visual and structural similarity to a brand, or enter your own domain to generate the protective-variant list worth registering or watching.
The defense workflow, end to end
Brand protection against typosquatting is a loop, not a one-time purchase. Each stage feeds the next.
<rect x="210" y="70" width="160" height="70" rx="8" fill="#ffffff" stroke="#2813e8" stroke-width="2"/>
<text x="290" y="100" text-anchor="middle" fill="#0f172a" font-weight="700">2. Register</text>
<text x="290" y="120" text-anchor="middle" fill="#334155" font-size="11">core set only</text>
<rect x="400" y="70" width="160" height="70" rx="8" fill="#ffffff" stroke="#2813e8" stroke-width="2"/>
<text x="480" y="100" text-anchor="middle" fill="#0f172a" font-weight="700">3. Monitor</text>
<text x="480" y="120" text-anchor="middle" fill="#334155" font-size="11">CT logs + WHOIS</text>
<rect x="590" y="70" width="160" height="70" rx="8" fill="#ffffff" stroke="#f59e0b" stroke-width="2"/>
<text x="670" y="100" text-anchor="middle" fill="#0f172a" font-weight="700">4. Take down</text>
<text x="670" y="120" text-anchor="middle" fill="#334155" font-size="11">UDRP / URS / abuse</text>
Which variants to register vs. monitor
Defensive registration is a budget decision. Buy the variants where the cost of not owning them is a live phishing site; monitor the rest.
| Variant type | Example | Register or monitor? | Why |
|---|---|---|---|
| Exact match, top TLDs | acmebank.net, acmebank.org | Register | Cheap insurance; these are the first ones attackers grab |
| Your country ccTLD | acmebank.co.uk, acmebank.de | Register | Regional customers assume it exists |
| Homoglyph twin (reads identically) | аcmebank.com (Cyrillic а) | Register if available | Pixel-identical in some fonts; highest phishing value |
| Top 1–2 fat-finger typos | acmbank.com, acmebnak.com | Register | Catches real mistyped traffic and denies the obvious lure |
| Long-tail typos | acmebankk.com, acmeban.com | Monitor | Hundreds of these; only act if weaponized |
| Combo-squats | acmebank-login.com, secure-acmebank.com | Monitor | Infinite space; watch CT logs and act on active abuse |
| Alternate new gTLDs | acmebank.bank, acmebank.xyz | Depends | Register .bank (restricted, trust signal); monitor speculative gTLDs |
| Which should I use? | — | Register the top ~10–20, monitor the rest | Registration is O(handful); monitoring is O(everything) |
What "weaponized" means — the takedown triggers
A registered lookalike sitting on a parking page is annoying, not urgent. Escalate when you see any of these:
| Signal | What it means | Response |
|---|---|---|
| MX records configured | The domain can send/receive mail — spoofing setup | Prepare takedown; warn staff/customers |
| A login/checkout page cloning your brand | Active credential phishing | Registrar + host abuse notice now; URS if new gTLD |
| A TLS certificate issued for the lookalike | Someone is standing up HTTPS — usually pre-launch | Watch closely; certificate is your early warning |
| Ads or redirects to competitors | Revenue diversion / brand dilution | UDRP for transfer; ACPA claim if in the U.S. |
| WHOIS shows bulk registration by one party | Organized cybersquatter | Bundle multiple domains into one UDRP complaint |
Legal takedown options compared
| Mechanism | Cost | Time | Outcome | Best for |
|---|---|---|---|---|
| Registrar/host abuse notice | Free | Hours–days | Suspension | Active phishing with clear harm |
| URS (Uniform Rapid Suspension) | ~$375 | ~3 weeks | Suspends (no transfer) | Clear-cut abuse in new gTLDs |
| UDRP (via WIPO/Forum) | ~$1,500+ | 2–3 months | Transfer or cancel | Trademark cases where you want the domain |
| ACPA lawsuit (U.S.) | Legal fees | Months+ | Damages + transfer | Egregious/repeat cybersquatters, $1k–$100k statutory damages per domain |
Rule of thumb: active phishing → abuse notice first (fastest harm reduction). Want the domain permanently → UDRP. Just want it dead in a new gTLD → URS.
Monitor with Certificate Transparency, not just WHOIS
The single highest-leverage monitoring source is Certificate Transparency. Because browsers require CT-logged certificates and nearly every phishing site now uses HTTPS, the attacker publishes their lookalike domain to a public, append-only log the moment they request a certificate — typically before the phishing page is even finished. Watching CT logs for your brand string gives you a lead time WHOIS-based monitoring can't match. Pair it with DMARC (p=reject) so exact-domain spoofing is blocked at the same time you're hunting lookalikes.
Enumerate your own exposure
To see the full variant space for your domain and check which lookalikes are already registered across every TLD, use our TLD Enumerator. Combine it with the Domain Spoofing Detector above to score how convincing each lookalike would be to a human.
Bottom line
You can't register every misspelling — the math doesn't allow it. Win instead by containing the highest-risk handful with defensive registration, watching Certificate Transparency for everything else, and having a rehearsed escalation path (abuse notice → URS → UDRP) so that when a lookalike goes hot, it's offline before it costs you a customer.